Is ServiceNow HIPAA Compliant

ServiceNow is one of the most widely used workflow automation platforms today. With its cloud-based architecture and ability to optimize the flow of information within an organization, it’s used for everything from tracking IT service requests to assisting medical triaging for patients.

With the right design, the power of ServiceNow is incredible. But is ServiceNow HIPAA compliant? 

ServiceNow HIPAA Compliance: What Makes a Software Tool HIPAA Compliant?

When it comes to software, there are specific indications of the tool’s HIPAA compliance. Software HIPAA compliance really boils down to two things. Does the application have safeguards to keep patient data private and secure? Does the software provider sign business associate agreements?

When the answer to both of these questions is “yes,” the tool is likely HIPAA compliant. If the answer to either is “no,” the tool is not HIPAA compliant.

Make Sure You’re HIPAA Compliant

Get business associate agreements to send to your vendors.

Become HIPAA Compliant

What Are HIPAA Safeguards?

HIPAA safeguards are measures that a healthcare organization puts into place to protect the confidentiality, integrity, and availability of protected health information (PHI). HIPAA categorizes safeguards into three groups – administrative, physical, and technical. 

Administrative safeguards are written policies and procedures that dictate the proper uses and disclosures of PHI.

Physical safeguards are measures that protect an organization’s physical location, such as locks and alarm systems.

Technical safeguards are measures that protect electronic PHI (ePHI).

While administrative and physical safeguards are important, technical safeguards are generally the determining factor of a software provider’s HIPAA compliance. Technical safeguards that you should keep an eye out for include encryption, user authentication, access controls, and audit controls.

Why is a Business Associate Agreement Important?

Business associate agreements are a key determinant of HIPAA compliance. Even the most secure software platform is NOT HIPAA compliant if they will not sign a business associate agreement (BAA). 

Why? 

A BAA is a legal agreement that requires each signing party to be HIPAA compliant and be responsible for maintaining compliance. As such, a BAA limits the liability for both signing parties in the event of a breach or OCR audit, as only the negligent party would be held culpable. 

Is ServiceNow HIPAA Compliant?

So, is ServiceNow HIPAA compliant? 

ServiceNow’s data security standards easily meet the requirements of the HIPAA Security Rule. The company is also willing to enter into a Business Associate Agreement, but there are clearly-stated limitations, which means ServiceNow’s HIPAA compliance is limited.

Specifically, ServiceNow will only enter into a BAA as a data processor, meaning their responsibility is to perform the actions requested by the data controller. The organization using the ServiceNow platform is responsible for all decisions concerning what data is stored and how it is used.

Within those parameters, ServiceNow appears to be HIPAA compliant.